OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63576

HIGH · CVSS 8.2 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability arises from improper certificate validation in the PkixNameConstraintValidator component of Bouncy Castle's bc-csharp library, affecting versions prior to 2.7.0. This flaw allows a malicious actor to bypass name constraints during certification path validation, potentially leading to unauthorized access or man-in-the-middle attacks by exploiting specially crafted URIs. Organizations utilizing this library for certificate validation should prioritize updating to the latest version to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63576
Severity
HIGH
CVSS
8.2
EPSS
0.22%

Original NVD Description

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded uniformResourceIdentifier name constraints during certification path validation via a URI whose path, query, fragment or userinfo contains characters such as '@' or ':', because the host was extracted by string slicing without first isolating the RFC 3986 authority component, so the host compared against the constraints could differ from the URI's actual host.